Impact
The Classified Listing - Mobile Number Verification plugin for WordPress fails to perform server‑side validation of Firebase OTP codes in its process_otp_login() function. Consequently, an unauthenticated user can submit a fabricated OTP code and UID through the Firebase OTP login flow and be authenticated as any user whose phone number is stored in the plugin’s phone table. The vulnerability allows an attacker to log in as any registered user, including administrators, if the phone number is known or guessed. Based on the description, it is inferred that the attacker must know or guess the target phone number to exploit this flaw.
Affected Systems
RadiusTheme’s Classified Listing - Mobile Number Verification WordPress plugin, all releases up to and including version 1.6.0. WordPress sites with this plugin installed, with Firebase OTP authentication enabled, and with phone numbers stored in the plugin’s phone table are at risk.
Risk and Exploitability
The CVSS base score of 8.1 confirms a high‑severity authentication bypass. No EPSS score is publicly published, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the target site has Firebase OTP login enabled and that the attacker knows or can correctly guess the user’s registered phone number. Based on the description, the likely attack vector is remote via the plugin’s public login endpoint and does not require local or administrative access on the server.
OpenCVE Enrichment